Anthropic launched its OSS Scanner last week as part of its broader Cyber Mission. According to the company, Claude has been scanning some of the world's most heavily used open source projects, generating over 29,000 potential vulnerability reports. The human review pipeline, which relies on six external security research firms, has worked through roughly 6,000 of those candidates. As of October 2, those firms had confirmed 5,674 of the 6,123 findings they reviewed as valid, but only 516 vulnerabilities had been fixed upstream by project maintainers.
To address the backlog, Anthropic is offering eligible open source projects an "optional fast-track" service. Instead of waiting for its own researchers to validate findings, the company sends periodic, unvalidated reports directly to maintainers, using its top models including Claude Mythos. Anthropic says it has already sent nearly 5,000 such unvalidated reports to maintainers who requested them.
Early testing of the scanner on 97 critical and high-severity findings across 48 projects showed 85 met the bar for disclosure, 11 were real bugs but duplicates, and only one was a false positive. However, those figures come from the scanner's initial output, not the full 29,000 candidates. Anthropic acknowledged that maintainers have reported inflated severity ratings and cases where the scanner misunderstood a project's threat model.
According to Anton Arapov, director of OpenSSL Corporation, the reports Anthropic sent — including raw model output — matched and sometimes beat expectations. The company says reports include a self-contained reproducer, identification of where the bug was introduced, and a candidate patch when possible.